arXiv:2501.11901cs.CV2025-01被引 1

通过分块变换提升对抗样本跨模型迁移能力

Enhancing Adversarial Transferability via Component-Wise Transformation

  • 对图像分块进行插值与选择性旋转,引导关注不同区域
  • 在ImageNet上跨架构攻击成功率显著优于现有方法
  • 适合研究对抗攻击迁移性或防御机制的读者

深度神经网络极易受到对抗样本的攻击,这在安全敏感应用中带来严峻挑战。基于输入变换的攻击策略在提升对抗样本迁移性方面表现突出,但现有方法在不同网络架构间性能仍不理想,尽管在同一架构内已取得良好效果。其根源在于:即使同架构模型也关注对象不同区域,而跨架构差异更显著,现有方法无法有效引导模型关注这些多样化区域。为此,本文提出一种新型基于输入变换的攻击方法——分块变换(Component-Wise Transformation, CWT)。CWT对图像分块分别施加插值和选择性旋转,使每个变换后的图像突出不同目标区域,从而增强对抗样本的迁移能力。在标准ImageNet数据集上的大量实验表明,CWT在跨CNN与Transformer模型的攻击成功率和稳定性上均持续优于当前最优方法。

原文摘要 · Abstract (English)

Deep Neural Networks (DNNs) are highly vulnerable to adversarial examples, which pose significant challenges in security-sensitive applications. Among various adversarial attack strategies, input transformation-based attacks have demonstrated remarkable effectiveness in enhancing adversarial transferability. However, existing methods still perform poorly across different architectures, even though they have achieved promising results within the same architecture. This limitation arises because, while models of the same architecture may focus on different regions of the object, the variation is even more pronounced across different architectures. Unfortunately, current approaches fail to effectively guide models to attend to these diverse regions. To address this issue, this paper proposes a novel input transformation-based attack method, termed Component-Wise Transformation (CWT). CWT applies interpolation and selective rotation to individual image blocks, ensuring that each transformed image highlights different target regions, thereby improving the transferability of adversarial examples. Extensive experiments on the standard ImageNet dataset show that CWT consistently outperforms state-of-the-art methods in both attack success rates and stability across CNN- and Transformer-based models.

对抗攻击迁移性图像变换

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。